CVE-2023-41359: Critical severity frrouting bgpd vulnerability
Published Aug 29, 2023
·Updated
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgpattraigpvalid in bgpd/bgpattr.c because there is no check for the availability of two bytes during AIGP validation.
Affected Software
6 affected componentsFixes available
redhat/frr<9.1
9.1
redhat/frr<8.5
8.5
Frrouting FRRouting<=9.0
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-41359?
The severity of CVE-2023-41359 is critical with a severity value of 9.1.
2
How does CVE-2023-41359 affect FRRouting?
CVE-2023-41359 affects FRRouting versions up to and including 9.0.
3
What is the vulnerability description of CVE-2023-41359?
CVE-2023-41359 is an out-of-bounds read vulnerability in bgp_attr_aigp_valid function in bgpd/bgp_attr.c of FRRouting.
4
How can CVE-2023-41359 be exploited?
CVE-2023-41359 can be exploited by causing an out-of-bounds read in bgp_attr_aigp_valid function during AIGP validation.
5
Is there a fix available for CVE-2023-41359?
Please refer to the official reference for the fix of CVE-2023-41359.